First published: Tue Jul 19 2016(Updated: )
Oracle Java SE 8u101 fixes an unspecified vulnerability in the Install component (<a href="https://access.redhat.com/security/cve/CVE-2016-3552">CVE-2016-3552</a>). Upstream has CVSS scored this issue as: 8.1/CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H External Reference: <a href="http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html#AppendixJAVA">http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html#AppendixJAVA</a>
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-oracle-1:1.8.0.101-1jpp.1.el6_8 | 1.8.0-oracle-1:1.8.0.101-1jpp.1.el6_8 |
redhat/java | <1.8.0-oracle-1:1.8.0.101-1jpp.1.el7 | 1.8.0-oracle-1:1.8.0.101-1jpp.1.el7 |
Oracle JDK 6 | =1.8.0-update92 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update92 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3552 has been scored as a severity of 8.1, indicating a high risk level.
To fix CVE-2016-3552, upgrade to Oracle Java SE version 1.8.0_101 or later.
CVE-2016-3552 affects Oracle Java SE 8u101 and earlier versions.
CVE-2016-3552 is classified as a local vulnerability that requires specific user interaction to exploit.
CVE-2016-3552 affects both the Java Development Kit (JDK) and the Java Runtime Environment (JRE) versions 1.8.0 update 92 and earlier.